CVE-2023-39346 is a critical remote code execution vulnerability affecting LinuxASMCallGraph software prior to commit 20dba06bd1a3cf260612d4f21547c25002121cd5. This flaw, rated 9.8 CVSS, allows unauthenticated attackers to execute arbitrary code on the server by uploading a specially crafted ZIP file due to insufficient input validation. While no known exploits or active exploitation have been reported, and community discussion is minimal, the high severity and ease of exploitation (AV:N/AC:L/PR:N/UI:N) warrant immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2022-02-08CPE matchmatch criteria | cpe:2.3:a:renjikai:linuxasmcallgraph:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.